Getting Data In

How can I search within the source names and source type names?

mdickey
Engager

I'm using an existing Splunk instance that already has hundreds of sources and source types. How can I search among the source names and source type names to find sources of interest? For example, I would like to know the names of all sources that contain the string "prod" in the source name itself.

0 Karma
1 Solution

lguinn2
Legend

That's easy, just search

| metadata type=sources | where match(source,"prod")

or

| metadata type=sourcetypes | where match(sourcetype,"prod")

to get just a list of the sourceytpes or sources, with a little info about each. Note that the match function uses regular expressions. To actually search the data, you can use

source="*prod*"

or

sourcetype="*prod*"

HTH

View solution in original post

lguinn2
Legend

That's easy, just search

| metadata type=sources | where match(source,"prod")

or

| metadata type=sourcetypes | where match(sourcetype,"prod")

to get just a list of the sourceytpes or sources, with a little info about each. Note that the match function uses regular expressions. To actually search the data, you can use

source="*prod*"

or

sourcetype="*prod*"

HTH

lguinn2
Legend

Thanks for the catch on the typo, I fixed it!

0 Karma

mdickey
Engager

Wow, that works like magic, thanks!!

One tiny typo in the second one:
match(sourcetypes,"prod")
should be
match(sourcetype,"prod")

Thanks again!

0 Karma

lguinn2
Legend

Updated my answer per your comments!

0 Karma

mdickey
Engager

Sorry, I must not have explained myself well. Your suggestion will search the actual event data. I don't want to search the data. I only want to get a back a list of source names that match. I want to search this list of source names themselves, not the data in the sources.

0 Karma
Get Updates on the Splunk Community!

Exporting Splunk Apps

Join us on Monday, October 21 at 11 am PT | 2 pm ET!With the app export functionality, app developers and ...

Cisco Use Cases, ITSI Best Practices, and More New Articles from Splunk Lantern

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Build Your First SPL2 App!

Watch the recording now!.Do you want to SPL™, too? SPL2, Splunk's next-generation data search and preparation ...